{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-007.json",
  "source": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-007",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-ASSURE-007",
    "profile": "assurance-and-evidence",
    "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-007",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-007.json",
    "title": "Machine-Readable Evidence in OSCAL",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Control results are emitted in a machine-readable standard format, OSCAL first (component-definition and assessment-results artefacts that trace each result back to the control it tested), and stored so that an auditor's question is answered by a query, not by collecting the evidence again.",
    "failureModes": [
      "Evidence reaches an audit as a screenshot or as a document a person formatted and filed by hand.",
      "An assessment result cannot be traced back to the control it tested.",
      "Each audit collects the evidence again from scratch."
    ],
    "scope": "The results of the controls of an AI stack that already produces structured records, and the assurance function that answers auditors from them. The choice of AI-specific OSCAL extensions is left open.",
    "enforcementPoints": [
      "runtime",
      "periodic"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "OSCAL assessment-results for each control result, with component definitions of the controls that produced them",
        "schemaId": null,
        "schema": null,
        "layer": 5
      },
      {
        "artefact": "Structured records the controls already produce, the starting point the pattern assumes (for example evidence records)",
        "schemaId": "evidence-record",
        "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
        "layer": 5
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "To be specified: the source material states no failure response for this control."
    },
    "layer": 5,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "machine-readable-evidence-oscal",
        "title": "Machine-Readable Evidence (OSCAL)",
        "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
      },
      {
        "slug": "continuous-assurance-telemetry",
        "title": "Continuous Assurance Telemetry",
        "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "machine-readable-evidence-oscal",
        "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
      },
      {
        "kind": "chapter",
        "ref": "patterns",
        "url": "https://aigovernanceengineer.com/bok/patterns"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART12",
          "name": "EU AI Act Art. 12 record-keeping and logging",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART17",
          "name": "EU AI Act Art. 17 quality management system",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art17"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART72",
          "name": "EU AI Act Art. 72 post-market monitoring",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72"
        },
        {
          "id": "AIGE-OBL-NISTRMF-MANAGE",
          "name": "MANAGE",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage"
        },
        {
          "id": "AIGE-OBL-NISTRMF-GOVERN",
          "name": "GOVERN",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern"
        }
      ],
      "iso42001": [],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 13,
        "title": "Pattern: Machine-Readable Evidence (OSCAL)",
        "text": "Pattern: Machine-Readable Evidence (OSCAL) (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal",
        "verified": "primary"
      },
      {
        "n": 14,
        "title": "OSCAL Layers and Models",
        "text": "OSCAL Layers and Models (control layer (catalog, profile), implementation layer (component-definition, system-security-plan) and assessment layer (assessment-plan, assessment-results, POA&M), with traceability from a result to the control it tested). NIST. 2026.",
        "url": "https://pages.nist.gov/OSCAL/learn/concepts/layer/",
        "verified": "primary"
      },
      {
        "n": 15,
        "title": "Making AI Compliance Evidence Machine-Readable (arXiv 2604.13767)",
        "text": "Making AI Compliance Evidence Machine-Readable (arXiv 2604.13767) (one proposed approach, a single preprint: OSCAL with sixteen property extensions for AI). UC3M. 2026-04-15.",
        "url": "https://arxiv.org/abs/2604.13767",
        "verified": "primary"
      },
      {
        "n": 3,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Build on OSCAL's native model first: the control layer (catalog, profile), the implementation layer (component-definition, system-security-plan) and the assessment layer (assessment-plan, assessment-results, POA&M), which traces a result back to the control it tested.",
      "AI-specific extensions are still forming: one 2026 preprint proposes sixteen property extensions; adopt them only where they fit, since the native assessment models carry most of the load today.",
      "An eval gate that writes an OSCAL assessment result on every run turns a request such as \"all robustness evidence in Q3\" into a filter over the store (the pattern's illustrative example)."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
      "Which OSCAL model should carry the result of an AI-specific control that no published catalogue defines: a local catalogue of these reference controls, or a property extension?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
